Problem: Need to create and add new wildcard SSL certificate to Unified Workspace server.
Prerequisite(s):
- Completed part 1
- Access to keystore password
Solution(s): Below instructions will walk you through process of placing a new keystore on Unified Workspace servers.
Configuring new keystore file:
- Copy wildcard.jks file in stoneware\config directory
- Repeat for all Unified Workspace servers
- Go to webAdmin
- Go to Relay Admin
- Click on first relay object
- Enable SSL (if not already enabled)
- Change certificate source to wildcard.jks
- Click Save button
- Repeat steps 5-8 for each additional relay objects
Entering new keystore password*:
- Go to Server Administrator console for any dedicated relays (https://127.0.0.1:8090)
- Go to Services tab
- Right-click on relay service
- Click Properties
- Change Relay User password to keystore password
IMPORTANT - must be same password as used in part 1 - Click Save button
- Go Settings
- Shutdown service
- Repeat steps 1-8 for any additional relays
- Repeat steps 1-8 for any servers+relays
- Go to your directory server tools (AD/eDir/OpenLDAP/AD LDS)
- Find relayuser account (default location is stoneware OU)
- Reset the relayuser password to match the keystore password
IMPORTANT - must be same password as used in part 1 - Configure relayuser account so password does not expire
- Start-up a server+relay
- Verify service has started up successfully
- Startup additional severs+relays
- Start-up additional dedicated relays
*If you have the current relayuser password documented, you can skip changing it in the directory and instead change keystore's and the keystore's keypair passwords to match what is already set in the directory.
Typically if you get any start-up error messages it's because the passwords have not been matched up correctly. Highly recommended to copy-n-paste with a complicated password.
Reference(s):
keywords:
keystore, SSL, java